掃碼下載
BTC $76,252.53 -1.03%
ETH $2,286.04 -0.38%
BNB $623.00 -0.31%
XRP $1.38 -1.25%
SOL $83.68 -1.02%
TRX $0.3227 -0.85%
DOGE $0.0994 +0.72%
ADA $0.2467 +0.01%
BCH $451.27 +0.54%
LINK $9.23 -0.33%
HYPE $40.04 -3.58%
AAVE $96.42 -1.31%
SUI $0.9237 -0.66%
XLM $0.1618 -1.57%
ZEC $335.56 -5.02%
BTC $76,252.53 -1.03%
ETH $2,286.04 -0.38%
BNB $623.00 -0.31%
XRP $1.38 -1.25%
SOL $83.68 -1.02%
TRX $0.3227 -0.85%
DOGE $0.0994 +0.72%
ADA $0.2467 +0.01%
BCH $451.27 +0.54%
LINK $9.23 -0.33%
HYPE $40.04 -3.58%
AAVE $96.42 -1.31%
SUI $0.9237 -0.66%
XLM $0.1618 -1.57%
ZEC $335.56 -5.02%

慢霧餘弦:Coinbase 曾遭 GitHub Actions CI/CD 機制供應鏈攻擊,建議企業自查相關風險

2025-03-23 16:07:55
收藏

ChainCatcher 消息,慢霧餘弦在 X 平台發文稱,利用 GitHub Actions CI/CD 機制供應鏈攻擊 Coinbase,所幸沒有繼續成功,否則下一個被爆的安全事件就是針對 Coinbase 了。在 GitHub 上的供應鏈攻擊路徑:reviewdog/action-setup -> tj-actions/changed-files -> coinbase/agentkit ->竊取 GitHub Personal Access Token(PAT)、雲服務有關密鑰等。餘弦建議,如果企業用到 reviewdog 或 tj-actions,應該進行自查。

app_icon
ChainCatcher 與創新者共建Web3世界